gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an application via a specific function call sequence. Only affects PHP when linked with an external libgd (not bundled).
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libgd | Libgd | 2.1.1 (including) | 2.2.5 (including) |
Libgd | Libgd | 2.1.0 (including) | 2.1.0 (including) |
Libgd | Libgd | 2.1.0-rc2 (including) | 2.1.0-rc2 (including) |
Red Hat Enterprise Linux 8 | RedHat | gd-0:2.2.5-7.el8 | * |
Doxygen | Ubuntu | devel | * |
Doxygen | Ubuntu | esm-apps/focal | * |
Doxygen | Ubuntu | esm-apps/jammy | * |
Doxygen | Ubuntu | esm-apps/noble | * |
Doxygen | Ubuntu | focal | * |
Doxygen | Ubuntu | groovy | * |
Doxygen | Ubuntu | hirsute | * |
Doxygen | Ubuntu | impish | * |
Doxygen | Ubuntu | jammy | * |
Doxygen | Ubuntu | kinetic | * |
Doxygen | Ubuntu | lunar | * |
Doxygen | Ubuntu | mantic | * |
Doxygen | Ubuntu | noble | * |
Doxygen | Ubuntu | oracular | * |
Doxygen | Ubuntu | trusty | * |
Libgd2 | Ubuntu | bionic | * |
Libgd2 | Ubuntu | devel | * |
Libgd2 | Ubuntu | eoan | * |
Libgd2 | Ubuntu | focal | * |
Libgd2 | Ubuntu | groovy | * |
Libgd2 | Ubuntu | hirsute | * |
Libgd2 | Ubuntu | impish | * |
Libgd2 | Ubuntu | jammy | * |
Libgd2 | Ubuntu | kinetic | * |
Libgd2 | Ubuntu | lunar | * |
Libgd2 | Ubuntu | mantic | * |
Libgd2 | Ubuntu | noble | * |
Libgd2 | Ubuntu | oracular | * |
Libgd2 | Ubuntu | trusty | * |
Libgd2 | Ubuntu | trusty/esm | * |
Libgd2 | Ubuntu | xenial | * |